Cisco DNA Digital Network Architecture Rui Brás Fernandes rbrasfer@cisco.com https://twitter.com/rbrasfer https://pt.linkedin.com/in/ruibrasfernandes
Cisco Vision and Strategy Vision Change the way the world works, lives, plays, and learns Strategy We create solutions built on intelligent networks that solve our customers' challenges
Digital Transformation Is Moving IT to the Boardroom UPS UPS My Choice Delivery Control Personalized Service Boeing Workforce Efficiency WIP Inventory and Part Tracking Starbucks Starbucks Apps Order Ahead Skip the Line Louis Vuitton Customer Experience Physical and Virtual RFID Content American Express American Express Personalized Service Through Mobile
And Creating New Priorities for Digital Organization Transform Processes and Business Models Innovations Faster Time to Market Empower Workforce Efficiency and Innovation Increased Productivity Better Retention Personalize Customer/ Citizen Experience Increased Loyalty Greater Insight Mobility IoT Analytics Cloud Mobile traffic will exceed wired traffic by 2017 IoT devices will triple by 2020 75% of companies planning to or investing in big data 80% of organizations will primarily use SaaS by 2018
A New Infrastructure for the Digital Organization Network
Network Requirements for the Digital Organization Insights & Experiences Abstraction, Intent, Policy Automation Verification of Desired Result Assurance Abstraction layer Automation & Assurance APIC EM Security & Compliance Using the Network as a Sensor for security threats and then Enforce Compliancy through Segmentation Visibility into Users behavior, Applications, Network performances Customer has the elements to make decision faster Wi-Fi Core WAN Cloud Drive Business Innovations Speed, Simplicity & Visibility Real-time and Dynamic Threat Defense
Evolution of Networking Software How do I deliver new applications? How do I improve security? How do I achieve speed and simplicity? How do I learn new software skills? How does this come together? Model- Driven Analytics Open APIs Open Compute Open Flow Network Functions Virtualization Standards Cloud Controllers Policy Overlays Cisco Digital Network Architecture Open Extensible Software-driven
Cisco Digital Network Architecture Network-enabled Applications Cloud Service Management Principles Open APIs Developers Environment Automation Abstraction and Policy Control from Core to Edge Policy Orchestration Open and Programmable Standards-Based Virtualization Analytics Network Data, Contextual Insights Physical and Virtual Infrastructure App Hosting Cloud-enabled Software-delivered Insights and Experiences Automation and Assurance Security and Compliance
Building on a Strong Foundation of Hardware and Software Innovation QFP QuantumFlow Processor IOS-XE The Evolution of IOS Virtualization Physical & Virtual Infrastructure App Hosting UADP Unified Access Data Plane Advanced, Multi-Core, Feature-Rich Routing Silicon Fully Programmable: leveraging the many features of IOS-XE with hardware performance Scalable: Massive number of CPU cores (40/64), ability to cascade multiple QFPs = consistent high performance Advanced on-chip QoS: 100,000+ hardware-based queues, sophisticated traffic shaping and control Secure: linkage to high-performance crypto capability for secure WAN transport Extensible Architecture: ability to scale both up and down the foundation for a long-lived family of high-performance, flexible routing silicon Taking the Proven Strengths of IOS to the Next Level Operational and Services Uniformity: Routing, Switching, and Wireless consistency New Foundational Capabilities: HA and operational leadership, state decoupling, net database Speed of Innovation Velocity: Code once and Re-use Many across multiple places in the network Foundation for Virtualization: providing for network hosting and integration of virtualized functions (VNFs, containers) Platform for the Future: the software stage for the next wave of Cisco innovation Flexible, Programmable, High-Performance Switching Silicon Fully Programmable: excellent flexibility, ability to handle new encaps (VXLAN, GPE, etc.) hardware speed, software elasticity Scalable: Massive recirculation bandwidth and low recirculation latency provide excellent tunneling and services support for traffic flows Advanced on-chip QoS: client level granularity, sophisticated bandwidth shaping, with integrated on-chip NetFlow for visibility Secure: integrated on-chip support for MACsec encryption (AES-128, CBC) Extensible Architecture: ability to scale both up and down the foundation for a long-lived family of highperformance, flexible switching silicon People that are really serious about software should build their own hardware 100% Cisco-developed programmable silicon: unlocking the power of DNA at hardware speeds
Configuration Source Evolution to a Policy Model Express Business Intent Translate into device specific policy/configuration Leverage Abstraction (the controller knows about the device specifics) Automate the Deployment across the Network Insure Fidelity to the Expressed Intent (keep everything in sync) Automation Controller-Led Networking Deployment Protected Assets De-coupling of Production Servers Development Servers Internet Access Employee User Identity PERMIT and DENY Topology PERMIT (managed asset) Employee PERMIT DENY PERMIT (Registered BYOD) Much easier to translate business Employee (Unknown BYOD) DENY DENY PERMIT objectives to network functionality ENG VDI System Lowers DENY TCO PERMIT PERMIT Policy based Configuration Dynamic, able to be automated by the Controller Over time Policy grows, static shrinks Today Controller-based Automation Policy Policy Policy User policy based on user identity and user-to-group mapping Traditional Traditional Traditional
Deploy, Report, Measure, Adjust, Repeat Analytics Network Data, Contextual Insights APIC EM Run Reports Deliver relevant content Applications Discover user insights Instrumentation Telemetry Correlation Network Measure and Adjust Click here to Correct Always Correct this way (and never ask me again) Analytics Endpoints Automated Deployment
Open Device Programmability RESTCONF NETCONF grpc Set Get Automate Open Device Programmability Data Model Configuration Operational Standard Device Specific Standard Device Specific Physical and Virtual Network Infrastructure Device Features Interface BGP QoS ACL Other vendors
Cloud Enabled Networking Cloud Service Management Policy Orchestration Cloud Connected Simplicity Speed Cloud Edge IaaS Scale Flexibility Cloud Delivered Innovation Insights VPC/ vdc Telemetry Continuous Innovation Cloud Enabled Audits CSR1000V vasa FTDv StrataWatch Plug & Play CMX Business Analysis Campus/HQ Branch Teleworker Campus/HQ WAN Teleworker Hybrid Cloud AWS Rackspace Azure Cisco Intercloud Campus/HQ Branch Teleworker Branch
What s New: Cisco DNA Innovations New! New! New! APIC-EM Automation Platform Completely New Platform Available Now Base Automation: Plug and Play Available Now Cloud version Controlled Availability, May 2016 Policy Services: IWAN App & EasyQoS Available Now March 2016, respectively Enterprise NFV Branch Service Virtualization Controlled Availability, March 2016 CMX Cloud Presence Analytics and Connect Available Now in US, April 2016 for ROW Network-enabled Applications Cloud Service Management Open APIs Developers Environment Automation Abstraction & Policy Control from Core to Edge Policy Orchestration Open & Programmable Standards-Based Virtualization Analytics Network Data, Contextual Insights Physical & Virtual Infrastructure App Hosting Cloud-enabled Software-delivered Available on DNA-Ready Infrastructure through Cisco ONE Software
Automation: Plug and Play New! Cisco ONE Foundation Cloud-Based Plug and Play Order Plug in and Cloud Provision Controller-Based Management 79% Lower deployment costs PnP Available Now PnP Cloud May 2016 (controlled availability) Eliminates Plug and play means no more IT engineers in the field faster time to market and dramatically lowered costs. Staging Truck Roll
Policy Service: IWAN Automation Optimal Branch Experience Made Easy Cisco ONE Foundation Available Now Simple Workflows 85% Faster deployments Zero-Touch Rollout Set Application Policy Gain Visibility and Tune IWAN Momentum 200+ deployments running up to 2500 sites Point and Click Troubleshoot IWAN automation eliminates tedious configuration tasks for advanced networking features. I can configure IWAN with just 10 GUI clicks. Transport- Independent Intelligent Path Control Application Optimization Highly Secure Connectivity
Policy Service: EasyQoS New! Cisco ONE Foundation Select from Predefined Policies Automated Deployment of QoS config Optimized for Any Infrastructure March 2016 General Availability in Cisco ONE May 2016 Improved Application Experience with No Operator Intervention Enhance Collaboration Experience Implements QoS in 250 ms 300% 50% Reduction in voice jitter Video quality improves The EasyQoS App reduces deployment times for network-wide QoS dramatically. We can now respond to changing application needs via policy-based automation within minutes or even seconds.
Software Control: Enterprise NFV New! Cisco ONE Foundation Full Software Stack to Increase Branch Agility Central Orchestration Management SDN: APIC-EM with Enterprise Service Automation Consistent, trusted network services Virtual Network Functions (VNFs): Cisco and Third Party Software Intelligence over Hardware Virtualization Layer: NFV Infrastructure Software Freedom of Choice Hardware: Cisco UCS E- and C-Series COTS Deploy Validated Designs in Minutes Cisco s approach to network functions virtualization (NFV) delivers the elasticity to invoke innovative capabilities in an optimal way whenever, wherever, and with whatever capacity they are required. March 2016 Controlled Availability: General Availability in Cisco ONE June 2016
Inside Cisco Enterprise NFV Cisco ONE Foundation 1 Select your network functions 2 Select your preferred infrastructure 3 Orchestrate and automate services vrouter Cisco ISR, UCS E-Series vfirewall Cisco UCS C-Series vwan optimization x86 server IT Agility Run on any platform vwlan controller Third-party services Elastic service scale Deploy in minutes EM APIC-EM with Enterprise Service Automation
Digital Services: CMX Cloud New! Cisco ONE Advanced Customer Insights and Engagement Presence Analytics Zone-based location analytics Connect Drag-and-drop customizable portal on demand Data on Storefront Conversion Frictionless Guest Onboarding Available now. General Availability in Cisco ONE June 2016 CMX Cloud has helped us quickly gain business insights, so we can enhance the shopper experience at Santana Row with easy Wi-Fi onboarding, increased customer data, and improved customer engagement.
Inside Cisco CMX Cloud Cisco ONE Advanced Gain Insights and Engage Customers SaaS consumption No MSE hardware required Deploy in less than 20 minutes 1 2 3 Subscribe to Cisco CMX Cloud and point to wireless infrastructure Collect analytics on user behavior Set up customized captive portal for guest onboarding Easy templates Multiple languages support Social logins Easily add logo and image Send relevant offers Capture user information
Cisco ONE Simplifies DNA Software Purchasing 1 Select Software Capabilities 3 Select Purchasing Model Advanced Application Advanced Security Traditional Cisco ONE Foundation Subscription 2 Select Platform Physical Virtual Wireless Switching Routing Enterprise Agreement
The Cisco DNA Customer Journey Starts Now Base Automation Policy Services Advanced Security Complete Software Control Digital Services Immediate value to existing network Active control for critical use cases: Network, Collaboration Network as a Sensor and Enforcer End-to-end policybased automation Support lines of business: analytics, IoT Cisco ONE Foundation Cisco ONE Adv. Applications Cisco ONE ELA
Begin Your Digital Journey Today ARE YOU READY: To automate network operations? Save on WAN transport? Enable richer collaboration experiences? Gain business insights? Deliver personalized customer experiences? Detect and remediate threats rapidly? To virtualize your branch? Cisco Digital Network Architecture
Helping You on the Journey Educate Enable Integrate Technology Tracks Learning Paths DevNet Zone DevNet membership 350,000+ 300+ Network Partners and Growing Roadshows and Pop-up Events DevNet Express Getting Started and API Reference Guides Sample Applications 1500+ Solutions Structured Training elearning Instructor-Led 40+ DevNet Learning Labs Community and Pay-for Developer Support 250+ Compatible Network Solutions Certification Program Coming in 2017 40+ Developer Sandboxes 9800+ Developers 4400+ Companies Cisco Professional Services 2500+ Partners Strong
THERE S NEVER BEEN A BETTER TIME